Red Team Intern · Cyberster
Mar 2026 — May 2026- End-to-end penetration tests across Linux, Windows, and Active Directory labs — passive OSINT to Domain-Admin compromise.
- OSINT and subdomain enumeration with Subfinder, Assetfinder, and OWASP Amass — 352 subdomains discovered, 21 live hosts validated via httpx & Gowitness.
- AS-REP Roasting, Kerberoasting, LLMNR/NBT-NS poisoning, GPO ACL abuse — reaching NT AUTHORITY\SYSTEM on domain controllers.
- Phishing campaigns with GoPhish and Havoc C2; AMSI bypass, LOLBAS, and payload obfuscation to evade endpoint defences in controlled labs.
- Documented findings in professional pentest reports mapped to CVSS and MITRE ATT&CK.